Home/Product/fig2dev project fig2dev
Product

fig2dev project fig2dev

30 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-46400
all versions
In xfig diagramming tool, a segmentation fault while running fig2dev allows an attacker to availability via local input manipulati
5.5MEDIUM
CVE-2025-46399
all versions
A flaw was found in fig2dev. This vulnerability allows availability via local input manipulation via genge_itp_spline function.
5.5MEDIUM
CVE-2025-46398
all versions
In xfig diagramming tool, a stack-overflow while running fig2dev allows memory corruption via local input manipulation via read_ob
5.5MEDIUM
CVE-2025-46397
all versions
A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline functio
7.8HIGH
CVE-2025-31164
all versions
heap-buffer overflow in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via create_li
6.6MEDIUM
CVE-2025-31163
all versions
Segmentation fault in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via put_patterna
6.6MEDIUM
CVE-2025-31162
all versions
Floating point exception in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via get_sl
6.6MEDIUM
CVE-2021-37530
<= 3.2.8a
A denial of service vulnerabiity exists in fig2dev through 3.28a due to a segfault in the open_stream function in readpics.c.
5.5MEDIUM
CVE-2021-37529
<= 3.2.8a
A double-free vulnerability exists in fig2dev through 3.28a is affected by: via the free_stream function in readpics.c, which coul
5.5MEDIUM
CVE-2021-32280
< 3.2.8
An issue was discovered in fig2dev before 3.2.8.. A NULL pointer dereference exists in the function compute_closed_spline() locate
5.5MEDIUM
CVE-2020-21535
all versions
fig2dev 3.2.7b contains a segmentation fault in the gencgm_start function in gencgm.c.
5.5MEDIUM
CVE-2020-21534
all versions
fig2dev 3.2.7b contains a global buffer overflow in the get_line function in read.c.
5.5MEDIUM
CVE-2020-21533
all versions
fig2dev 3.2.7b contains a stack buffer overflow in the read_textobject function in read.c.
5.5MEDIUM
CVE-2020-21532
all versions
fig2dev 3.2.7b contains a global buffer overflow in the setfigfont function in genepic.c.
5.5MEDIUM
CVE-2020-21531
all versions
fig2dev 3.2.7b contains a global buffer overflow in the conv_pattern_index function in gencgm.c.
5.5MEDIUM
CVE-2020-21530
all versions
fig2dev 3.2.7b contains a segmentation fault in the read_objects function in read.c.
5.5MEDIUM
CVE-2020-21529
all versions
fig2dev 3.2.7b contains a stack buffer overflow in the bezier_spline function in genepic.c.
5.5MEDIUM
CVE-2020-21684
all versions
A global buffer overflow in the put_font in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS) via
5.5MEDIUM
CVE-2020-21683
all versions
A global buffer overflow in the shade_or_tint_name_after_declare_color in genpstricks.c of fig2dev 3.2.7b allows attackers to caus
5.5MEDIUM
CVE-2020-21682
all versions
A global buffer overflow in the set_fill component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DOS
5.5MEDIUM
CVE-2020-21681
all versions
A global buffer overflow in the set_color component in genge.c of fig2dev 3.2.7b allows attackers to cause a denial of service (DO
5.5MEDIUM
CVE-2020-21680
all versions
A stack-based buffer overflow in the put_arrow() component in genpict2e.c of fig2dev 3.2.7b allows attackers to cause a denial of
5.5MEDIUM
CVE-2020-21678
all versions
A global buffer overflow in the genmp_writefontmacro_latex component in genmp.c of fig2dev 3.2.7b allows attackers to cause a deni
5.5MEDIUM
CVE-2020-21676
all versions
A stack-based buffer overflow in the genpstrx_text() component in genpstricks.c of fig2dev 3.2.7b allows attackers to cause a deni
5.5MEDIUM
CVE-2020-21675
all versions
A stack-based buffer overflow in the genptk_text component in genptk.c of fig2dev 3.2.7b allows attackers to cause a denial of ser
5.5MEDIUM
CVE-2021-3561
all versions
An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker to provide
7.1HIGH
CVE-2019-19797
all versions
read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write.
5.5MEDIUM
CVE-2019-19746
all versions
make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow vi
5.5MEDIUM
CVE-2019-14275
all versions
Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the calc_arrow function in bound.c.
5.5MEDIUM
CVE-2018-16140
all versions
A buffer underwrite vulnerability in get_line() (read.c) in fig2dev 3.2.7a allows an attacker to write prior to the beginning of t
7.8HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin